发布于2026.04.07 备注:OpenHarmony 5.0阶段各分支中当前主要对OpenHarmony-5.0.3-Release分支进行安全漏洞维护。 CVE漏洞描述漏洞影响CVSS3.1基础得分受影响的版本受影响的仓库修复链接 CVE-2026-24792web_webview条件竞争漏洞远程攻击者可造成任意代码执行8.1OpenHarmony-v6.0-Releaseweb_webview6.0.x CVE-2026-27648web_webview越界写漏洞远程攻击者可造成任意代码执行8.8OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v5.0.3-Releaseweb_webview6.0.x 5.1.0.x 5.0.3.x CVE-2026-27781kernel_liteos_a整数溢出漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.0.3-Release OpenHarmony-v5.1.0-Releasekernel_liteos_a5.1.0.x 5.0.3.x CVE-2026-28751filemanagement_storage_service输入校验漏洞本地攻击者可造成DOS3.3OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v5.0.3-Releasefilemanagement_storage_service6.0.x 5.1.0.x 5.0.3.x CVE-2026-25110Sensors_medical_sensor空指针解引用漏洞本地攻击者可造成DOS3.3OpenHarmony-v6.0-Release OpenHarmony-v5.0.3-ReleaseSensors_medical_sensor6.0.x 5.0.3.x 以下为三方库漏洞,只提供CVE、严重程度、受影响的OpenHarmony版本,详细信息请参考三方公告。 CVE严重程度CVSS 3.1得分受影响的仓库受影响的OpenHarmony版本修复链接 CVE-2026-25646中危6.3third_party_libpngOpenHarmony-v6.0-Release6.0.x CVE-2026-22693中危5.3third_party_harfbuzzOpenHarmony-v6.0-Release6.0.x CVE-2026-1757中危6.2third_party_libxml2OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x CVE-2026-0992低危2.9third_party_libxml2OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x CVE-2026-0990中危5.9third_party_libxml2OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x CVE-2026-0989低危3.7third_party_libxml2OpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x CVE-2025-9230高危7.5third_party_opensslOpenHarmony-v5.1.0-Release OpenHarmony-v6.0-Release OpenHarmony-v5.0.3-Release6.0.x 5.1.0.x 5.0.3.x CVE-2025-8194高危7.5third_party_pythonOpenHarmony-v6.0-Release6.0.x CVE-2025-28164无尚未提供third_party_libpngOpenHarmony-v6.0-Release6.0.x CVE-2025-28162无尚未提供third_party_libpngOpenHarmony-v6.0-Release6.0.x 以下是各维护版本的安全补丁标签,请在合入当月及之前全部对应安全补丁之后,更新安全补丁标签。 对应维护版本安全补丁修改方式参考链接 6.0.xhttps://gitcode.com/openharmony/startup_init/pull/4492 5.1.0.xhttps://gitcode.com/openharmony/startup_init/pull/4470 5.0.3.xhttps://gitcode.com/openharmony/startup_init/pull/4493
participants (1)
-
王晨